Skip to content

ci: bump codeql-action to 4.37.9 and group dependabot updates - #1240

Open
DaleSeo wants to merge 1 commit into
mainfrom
ci/group-codeql-action-updates
Open

ci: bump codeql-action to 4.37.9 and group dependabot updates#1240
DaleSeo wants to merge 1 commit into
mainfrom
ci/group-codeql-action-updates

Conversation

@DaleSeo

@DaleSeo DaleSeo commented Sep 2, 2026

Copy link
Copy Markdown
Member

Motivation and Context

Since #1216 pinned actions to commit SHAs, Dependabot stopped treating github/codeql-action as a single dependency and began opening separate PRs per sub-action. Each of those PRs fails every CodeQL.

This PR bumps all three steps to the same v4.37.9 SHA and adds a Dependabot groups entry matching github/codeql-action*, so future bumps arrive as one PR.

How Has This Been Tested?

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actions github-actions Bot added T-CI Changes to CI/CD workflows and configuration T-config Configuration file changes labels Sep 2, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review September 2, 2026 04:01
@DaleSeo
DaleSeo requested a review from a team as a code owner September 2, 2026 04:01
@DaleSeo DaleSeo self-assigned this Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-CI Changes to CI/CD workflows and configuration T-config Configuration file changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant